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"SMS* ” 


2 3 AUG 1971 


MEMORANDUM FORi Acting Chief, DDS Plan* Staff 

SUBJECT : Comment* on Preliminary Draft of FY 1971 

PFIAB Report 


1. The extracts of the preliminary draft of the FY 1971 
PFIAB Report forwarded on 17 August 1971 with a request for com- 
ments and/or revisions have been reviewed, 

2. The Office of Security concurs in the content of the extracts 
with the exception of the paragraph outlining computer security 
activities on the final page of Section IV (Information Processing and 
Exploitation). 

3. This paragraph, which begins ‘’Computer security is ... . 
more appropriately belongs under its own heading Computer Security 
as a lettered subsection of Counterintelligence in the sequence 
enumerated as Personnel Security. Physical Security, and Communi - 
cations Security . In addition, it should be amended and expanded to 
he more truly representative of our FY 1971 computer security 
activities. 


4. I would, therefore, suggest deletion of the noted paragraph 
in Section IV and inclusion of the following as an additional lettered 
subsection under Counterintelligence: 

X. Computer Security 

Computer security continues as an area of increasing 
Agency concern and attention. Our capabilities for addressing 
ADP security problems were greatly enhanced during FY 1971 
by the assignment of additional personnel to our computer 
security program and the acquisition of increased technical 
competence. 
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Daring the year the responsibilities of our Office of 
Security in this a rest were further refined to includes (1) 
Development of uniform computer security policy and stan- 
dards for Agency implementation; (2) Initiation of a coordi- 
nated Agency program for the identification and resolution 
of ADP Security problems; (3) Provision of continuing 
guidance to Agency computer components in handling the 
security problems related to modern information processing 
techniques; (4) Conduct of security audit of Agency computer 
operations, to include the security analysis, testing, and 
e valuation of our computer systems; and (5) Support of other 
government computer security efforts where the Agency is 
requested to provide assistance. 

Specific computer security efforts initiated and/or com- 
pleted in the fiscal year included the following: 

(1 s Development of Agency security standards and 
procedures for the installation and operation of re- 
mote terminal devices. 

(2) A review of Agency control procedures for com- 
puter storage media, a. g, , magnetic tapes. 

(3) Recommendations for improvements in design of 
security features in the Generalised Information Manage 
men! System (GIMP) software package. 


(4) Development of methods to inhibit user entry into 
the supervisor state of software used on some Agency 
systems. 

(5) Inauguration of a four -week part-time computer 
security seminar for both security officers and com- 
puter specialists. 

(6) Continuing support in the form of computer security 
guidance and inspections to computer operations at 
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Agency Headquarter* and at selected contractor sites. 

{7} Continued security support of community A DP efforts, 
especially those of the US IB Computer Security Subcommittee. 
The Agency has also provided assistance to other govern* 
mental groups or has at least monitored such other efforts 
relating to the protection of data in modern computer 
systems; among these efforts have been the activities of 
the Computer Science and Engineering Board of the National 
Academy of Sciences and the United States Communications 
Security Board. 


25X1 A9a 


Acting ISirector of Security 
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